CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityMedium
An e-commerce company processes credit card payments through its cloud application. To reduce the number of systems that fall under PCI DSS audit scope, the company replaces stored card numbers with randomly generated surrogate values that have no exploitable value if breached. Which technique is being used?
- AHashing
- BNetwork segmentation
- CData masking
- DTokenization
Show answer & explanationAnswer & explanation
Correct answer: D. Tokenization
Tokenization replaces sensitive cardholder data with a non-sensitive token that has no exploitable value, which reduces the number of systems storing actual card data and thus shrinks PCI DSS audit scope.
Why the other options are wrong
- A. Hashing creates a one-way fixed-length representation but is not typically reversible for payment processing needs.
- B. Network segmentation isolates systems handling card data but doesn't replace the data itself.
- C. Data masking obscures data for display purposes but doesn't necessarily remove it from storage entirely.
Tokenization (PCI DSS)
A technique that replaces sensitive cardholder data with a non-sensitive placeholder token, reducing the systems in scope for PCI DSS compliance.
- Tokens have no exploitable value if stolen
- Reduces number of systems requiring PCI DSS audit
- Different from encryption, which is reversible with a key
Memory trick: Token = a 'fake coin' that's worthless to thieves